OpenA2A Agent Identity Protocol (OpenA2A AIP)

August 6, 2026 · View on GitHub

OpenA2A specs · did:opena2a · AIP · ATX · ATP · AAP · AIM · all specs ↗

OpenA2A Agent Identity Protocol (OpenA2A AIP)

OpenA2A's open standard for AI agent identity, capabilities, and trust.

OpenA2A AIP answers "Who is this agent, what can it do, and should I trust it?" with cryptographic identity, structured capabilities, and multi-factor trust scoring.

Naming note. Multiple independent specifications use the abbreviation "AIP" for "Agent Identity Protocol" (see Naming and prior art below). When referenced outside this repository, please use the fully qualified name "OpenA2A AIP" to disambiguate. The bare "AIP" is retained inside this repository where context is unambiguous.

Contributing

This specification is early and authored in the open. We are looking for co-authors, an independent second implementation, and security review before it goes to an external standards body. See CONTRIBUTING.md.

Quick Start

# Create an agent identity
npx opena2a-cli identity create --name my-agent

# Verify an agent
curl "https://aim.opena2a.org/api/v1/did/did:aip:aim_7f3a9c2e"

# Discover an identity provider
curl https://aim.opena2a.org/.well-known/aip

Specification

AIP-SPEC.md — the full protocol specification.

Conformance Levels

LevelNameWhat It Means
1Local IdentitySDK/CLI keypair. No server needed.
2Managed Identity+ verification, trust scoring, audit.
3Federated Identity+ DIDs, verifiable credentials, cross-platform.

Interoperability

AIP is designed to complement:

How AIP and ATP Work Together

AIP (identity + behavior)     ATP (code + provenance)
  "Who is this agent?"           "Is this agent's code safe?"
         ↓                              ↓
              Combined Trust Decision
              "Is this agent safe to use?"

Reference Implementation

The OpenA2A AIM Platform implements AIP at Level 2.

Naming and prior art

The abbreviation "AIP" for "Agent Identity Protocol" appears in at least three independent specifications as of mid-2026. Implementers comparing options should be aware of this collision and pin to the fully qualified name when referencing any of them.

SpecAuthorsFirst publicationScope
OpenA2A AIP (this repository)OpenA2AMarch 2026Identity, capabilities, verification, trust scoring, governance, lifecycle, audit. Reference implementation in AIM.
draft-aip-agent-identity-protocol-00James Cao, Carlos Eduardo Arango Gutierrez (NVIDIA)March 16, 2026Two-layer model: unique agent identity with cryptographic signing + policy enforcement through an interposing proxy.
draft-singla-agent-identity-protocol-00Paras Singla (Independent)April 17, 2026Decentralized identity + delegation; introduces the did:aip DID method, capability-based authorization, cryptographic delegation chains.

The three specs are independent of one another. OpenA2A AIP has the broadest surface (identity through audit), the Cao/Arango draft is closest to OpenA2A AIP's capability + enforcement scope, and the Singla draft overlaps with OpenA2A's did:opena2a method on the DID-method axis (did:aip vs did:opena2a).

OpenA2A's position is that the three specs solve adjacent but distinct problems and that coordination on shared vocabulary is preferable to a name fight. Outreach to the IETF draft authors is tracked separately. In the meantime, the "OpenA2A AIP" branding in this repository is the unilateral disambiguation step.

License

Apache-2.0